Controller and Contact
The data controller is Shinuda. Privacy contact: help@shinuda.cc.
Data We Process
- Account and authentication data, including account identifiers, email verification state, hashed email identifiers, password hashes, token hashes, account roles, account tier, and timestamps.
- Security and technical data, including request identifiers, IP addresses or network identifiers used for security and rate limiting, coarse request route, response status, coarse authentication state, rate-limit events, and audit events needed to protect the service.
- Encrypted sync, plugin data, cache, plugin-secret snapshots, device key envelopes, and server-hosted secret bundles. The server stores ciphertext, nonces, key identifiers, revisions, and ciphertext hashes, not plaintext private libraries, settings, watch history, secrets, private keys, or provider tokens.
- Plugin store and publisher data, including plugin metadata, release versions, public signing keys, review states, reports, installation records, and publisher terms acceptances.
- Billing and entitlement data received from payment providers, such as customer references, transaction, subscription, and adjustment identifiers, selected plan, payment or adjustment action and status, currency, amount, billing-period dates, and limited payment metadata needed to activate access and resolve billing support. Shinuda does not store complete payment card details.
- Aggregate server-hosted usage associated with a billing adjustment, including the allowance window, operation count, and consumed compute points. We do not attach private media, plugin secrets, or plaintext synchronized content to this billing-usage snapshot.
- Support data that a user voluntarily sends, such as diagnostic bundles or messages to support.
Purposes
We process data to provide accounts, sync between devices, operate the plugin store, support plugin publication, activate and manage paid entitlements, enable household and server-hosted features, protect the service, prevent abuse, comply with legal obligations, and respond to user requests.
Legal Bases
Where GDPR applies, we rely on contract performance, steps requested before entering a contract, legitimate interests in security and service operation, consent where required, and legal obligations.
Membership Status and Premium Access
When Patreon reports a membership change, Shinuda updates the related Premium entitlement. If paid membership access ends, the household returns to its otherwise available tier; local and Free use remain available.
You may contact help@shinuda.cc to ask for an explanation or manual review if you believe an entitlement is wrong. Mandatory consumer and data-protection rights remain unaffected.
Encryption and Limited Visibility
Shinuda is designed so private user content and secrets are client-encrypted or sent as encrypted bundles. We do not ask for plaintext plugin secrets, private keys, private library content, private history, or provider tokens, and the server is not designed to decrypt user ciphertext. Passwords are hashed, user domain records are pseudonymized, and operational access is limited to service and security needs.
Plugins and Third-Party Content
Plugins may be created by third-party publishers or installed by users outside the official store. Shinuda does not host pirated plugins, authorize license circumvention, DRM circumvention, or copyright infringement, and is not responsible for plugins, sources, configurations, or content added by users outside the controlled store process. Users and publishers are responsible for the legality of their plugins, data sources, and usage.
Sharing
We may use infrastructure, database, object storage, email, security, monitoring, and support providers to operate the service. Patreon processes membership and transaction data under its own privacy terms and provides Shinuda with the information needed to manage entitlements.
We do not sell personal data or share it with third parties for their own advertising. We may disclose data to public authorities only where required by law or necessary to protect rights, safety, and service integrity.
Website Preferences and Cookies
The Shinuda website stores a language-preference cookie named shinuda_locale for up to one year so it can open the requested language. The current website does not use this cookie for advertising or cross-site tracking. A checkout, payment provider, download host, or other third-party service may use its own cookies under its own policy.
International Transfers
If technical providers process data outside the European Economic Area, we use legally required safeguards such as adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms.
Retention
We keep data for as long as needed for account operation, sync, billing adjustments, payment-dispute handling, security, accountability, support, and legal obligations. Adjustment enforcement may retain the provider action, status, amount, currency, timestamps, and an aggregate usage snapshot while the account exists. After account deletion, we delete or anonymize user-scoped records according to service architecture, except where retention is required for security, abuse prevention, accountability, or law.
Children
Shinuda is not directed to children who cannot validly agree to these terms or data processing under the law where they live. A minor may use the service only with the permission and supervision required by applicable law. If we learn that personal data was submitted without the required authorization, contact help@shinuda.cc so we can take appropriate action.
Security and Incidents
We use technical and organizational safeguards appropriate to the service, including encryption in transit, password hashing, access controls, pseudonymization, scoped credentials, and monitoring. No system is completely secure. If a personal-data incident requires notice under applicable law, we will notify affected users and the competent authority as required.
Account Deletion
You may delete your account using the available account controls or request help at help@shinuda.cc. Deletion is permanent and may make encrypted data unrecoverable. We delete or anonymize user-scoped data according to the service's deletion workflow, while limited records may be retained where required for payment, tax, security, fraud prevention, dispute handling, or other legal obligations. Residual copies may remain in protected backups until their normal expiry.
Your Rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, objection to legitimate-interest processing, and withdrawal of consent without affecting prior lawful processing. You may also complain to a competent data protection authority.
Policy Updates
We may update this policy when the service, providers, or legal requirements change. The current version and its update date are published on this page. Where required by law, we will provide additional notice or request consent before a material change takes effect.